Input validation error in Apache Santuario XML Security for Java - CVE-2022-47966
Published: January 17, 2023 / Updated: February 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to unspecified error in the Apache Santuario, which affects Zoho ManageEngine products, when SAML SSO is enabled. A remote non-authenticated attacker can bypass authentication process and compromise the affected system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
ManageEngine Access Manager Plus
Zoho ManageEngine Active Directory 360
OS Deployer
Remote Monitoring and Management (RMM)
Zoho ManageEngine ADAudit Plus
Endpoint DLP
Patch Manager Plus
Vulnerability Manager Plus
Device Control Plus
ManageEngine Application Control Plus
Endpoint Central
Endpoint Central MSP
ManageEngine Browser Security Plus
ManageEngine Analytics Plus
PAM 360
Key Manager Plus
Password Manager Pro
Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine Remote Access Plus
Zoho ManageEngine ServiceDesk Plus
ManageEngine AssetExplorer
Zoho ManageEngine ADSelfService Plus
Zoho ManageEngine ADManager Plus
Zoho ManageEngine SupportCenter Plus
How to mitigate CVE-2022-47966
ManageEngine Access Manager Plus - update to 4.3 4308
OS Deployer - update to 1.1.2243.1
Remote Monitoring and Management (RMM) - update to 10.1.41
Endpoint DLP - update to 10.1.2137.6
Patch Manager Plus - update to 10.1.2220.18
Vulnerability Manager Plus - update to 10.1.2220.18
Device Control Plus - update to 10.1.2220.18
ManageEngine Application Control Plus - update to 10.1.2220.18
Endpoint Central - update to 10.1.2228.11
Zoho ManageEngine Remote Access Plus - update to 10.1.2228.11
Endpoint Central MSP - update to 10.1.2228.11
ManageEngine Browser Security Plus - update to 11.1.2238.6
Zoho ManageEngine ServiceDesk Plus - update to 14.0 14004
Zoho ManageEngine Active Directory 360 - update to 4310
ManageEngine Analytics Plus - update to 5150
PAM 360 - update to 5713
Zoho ManageEngine ADSelfService Plus - update to 6211
Key Manager Plus - update to 6401
ManageEngine AssetExplorer - update to 6983
Zoho ManageEngine ADAudit Plus - update to 7081
Zoho ManageEngine ADManager Plus - update to 7162
Zoho ManageEngine SupportCenter Plus - update to 11026
Password Manager Pro - update to 12124
Zoho ManageEngine ServiceDesk Plus MSP - update to 13001
Links to Public Exploits and PoC-codes
- Exploit #8815 - ManageEngine Endpoint Central Unauthenticated SAML RCE (February 8, 2023)
- Exploit #8805 - ManageEngine ADSelfService Plus Unauthenticated SAML RCE (February 8, 2023)
- Exploit #8797 - ManageEngine ServiceDesk Plus Unauthenticated SAML RCE (February 7, 2023)
- Exploit #8769 - CVE-2022-47966-Scan (Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.) (January 25, 2023)
- Exploit #8764 - CVE-2022-47966 (The manage engine mass loader for CVE-2022-47966) (January 23, 2023)
- Exploit #8753 - CVE-2022-47966 (POC for CVE-2022-47966 affecting multiple ManageEngine products) (January 19, 2023)
- Exploit #8752 - PoC-for-ME-SAML-Vulnerability (PoC for cve-2022-47966) (January 19, 2023)